WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 14,301–14,350 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 287 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium SKT Addons for Elementor Plugin skt-addons-for-elementor Cross-Site Scripting ≤ 3.0 CVE-2024-38674 Patchstack
6.5 Medium Arkhe Blocks Plugin arkhe-blocks Cross-Site Scripting ≤ 2.22.1 CVE-2024-38675 Patchstack
6.5 Medium Booking Ultra Pro Plugin booking-ultra-pro Cross-Site Scripting ≤ 1.1.13 CVE-2024-38676 Patchstack
6.5 Medium REVIEWS.io Plugin reviewscouk-for-woocommerce Cross-Site Scripting ≤ 1.2.7 CVE-2024-38677 Patchstack
6.5 Medium Calendar.online / Kalender.digital Plugin kalender-digital Cross-Site Scripting Plugin plugin <= 1.0.8 - Cross Site Scripting (XSS) ≤ 1.0.8 Fixed in 1.0.9 CVE-2024-38678 Patchstack
6.5 Medium Animated Typed JS Shortcode Plugin animated-typed-js-shortcode Cross-Site Scripting ≤ 2.0 CVE-2024-38679 Patchstack
6.5 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Cross-Site Scripting ≤ 1.1.41 Fixed in 1.1.42 CVE-2024-38681 Patchstack
6.5 Medium Post Layouts for Gutenberg Plugin post-layouts Cross-Site Scripting ≤ 1.2.7 CVE-2024-38682 Patchstack
6.5 Medium SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Plugin slingblocks Cross-Site Scripting ≤ 1.4.1 Fixed in 1.5.0 CVE-2024-38684 Patchstack
5.9 Medium WP Announcement Plugin sp-announcement Cross-Site Scripting ≤ 2.0.8 Fixed in 2.0.9 CVE-2024-38685 Patchstack
6.5 Medium FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor Plugin post-block Cross-Site Scripting ≤ 5.3.1 Fixed in 5.3.2 CVE-2024-38686 Patchstack
6.5 Medium Sky Addons for Elementor Plugin sky-elementor-addons Cross-Site Scripting ≤ 2.5.5 Fixed in 2.5.8 CVE-2024-38687 Patchstack
5.9 Medium Simple Popup Plugin simple-popup-plugin Cross-Site Scripting ≤ 4.4 Fixed in 4.5 CVE-2024-38689 Patchstack
6.5 Medium Goftino Plugin goftino Cross-Site Scripting ≤ 1.6 Fixed in 1.7 CVE-2024-38697 Patchstack
6.5 Medium SKT Skill Bar Plugin skt-skill-bar Cross-Site Scripting ≤ 2.0 Fixed in 2.1 CVE-2024-38698 Patchstack
6.5 Medium WP Event Aggregator Plugin wp-event-aggregator Cross-Site Scripting ≤ 1.7.9 Fixed in 1.8.0 CVE-2024-38703 Patchstack
6.5 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Cross-Site Scripting ≤ 1.2.4 Fixed in 1.2.5 CVE-2024-38705 Patchstack
5.9 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin <= 2.0.6.2 - Cross Site Scripting (XSS) ≤ 2.0.6.2 Fixed in 2.0.6.3 CVE-2024-38710 Patchstack
6.5 Medium Qi Blocks Plugin qi-blocks Cross-Site Scripting ≤ 1.3 Fixed in 1.3.1 CVE-2024-38712 Patchstack
6.5 Medium WP Photo Album Plus Plugin wp-photo-album-plus Cross-Site Scripting Authenticated Stored Cross Site Scripting (XSS) ≤ 8.8.02.002 Fixed in 8.8.02.003 CVE-2024-38713 Patchstack
6.5 Medium Download Button for Elementor Plugin download-button-for-elementor Cross-Site Scripting ≤ 1.2.1 CVE-2024-38718 Patchstack
6.5 Medium EazyDocs Plugin eazydocs Cross-Site Scripting ≤ 2.5.0 CVE-2024-38720 Patchstack
6.5 Medium Job Board Manager Plugin job-board-manager Cross-Site Scripting ≤ 2.1.57 CVE-2024-38722 Patchstack
5.9 Medium Admin Dashboard RSS Feed Plugin admin-dashboard-rss-feed Cross-Site Scripting ≤ 3.1 CVE-2024-38725 Patchstack
5.9 Medium Change From Email Plugin wp-from-email Cross-Site Scripting ≤ 1.2.1 CVE-2024-38738 Patchstack
5.1 Medium OnePress Theme onepress Cross-Site Scripting ≤ 2.3.8 CVE-2024-38739 Patchstack
6.5 Medium Amazing Hover Effects Plugin amazing-hover-effects Cross-Site Scripting ≤ 2.4.9 CVE-2024-38741 Patchstack
6.5 Medium Advanced post slider Plugin advanced-post-slider Cross-Site Scripting ≤ 3.0.0 CVE-2024-38750 Patchstack
6.5 Medium Typebot Plugin typebot Cross-Site Scripting ≤ 3.6.0 Fixed in 3.6.1 CVE-2024-38757 Patchstack
6.5 Medium BSK PDF Manager Plugin bsk-pdf-manager Cross-Site Scripting ≤ 3.6 Fixed in 3.6.1 CVE-2024-38767 Patchstack
4.9 Medium WappPress Plugin wapppress-builds-android-app-for-website Server-Side Request Forgery Blind Server Side Request Forgery (SSRF) ≤ 6.0.4 CVE-2024-38758 Patchstack
5.3 Medium Getwid – Gutenberg Blocks Plugin getwid Broken Access Control Gutenberg Blocks <= 2.0.10 - Missing Authorization to Google API key update No login needed ≤ 2.0.10 CVE-2024-6489 Wordfence
4.3 Medium Getwid – Gutenberg Blocks Plugin getwid Broken Access Control Gutenberg Blocks <= 2.0.10 - Missing Authentication to MailChimp API key update ≤ 2.0.10 CVE-2024-6491 Wordfence
6.5 Medium Mercado Pago payments for WooCommerce Plugin woocommerce-mercadopago Path Traversal Authenticated (Subscriber+) Arbitrary File Download 7.3.0 – 7.6.1 CVE-2024-3934 Wordfence
5.3 Medium Addonify – Quick View For WooCommerce Plugin addonify-quick-view Information Disclosure Quick View For WooCommerce <= 1.2.16 - Unauthenticated Full Path Dislcosure No login needed ≤ 1.2.16 CVE-2024-6560 Wordfence
6.4 Medium Easy Testimonials Plugin easy-testimonials Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.9.5 CVE-2024-2337 Wordfence
4.3 Medium Conditional Fields for Contact Form 7 Plugin cf7-conditional-fields Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Setting Reset No login needed ≤ 2.4.13 CVE-2024-5804 Wordfence
5.4 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 3.13.0 - Insecure Direct Object Reference to Authenticated (GiveWP Worker+) Arbitrary Post Actions ≤ 3.13.0 CVE-2024-5977 Wordfence
4.3 Medium YITH Essential Kit for WooCommerce #1 Plugin yith-essential-kit-for-woocommerce-1 Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Plugin Install, Activation, and Deactivation ≤ 2.34.0 CVE-2024-6799 Wordfence
5.9 Medium Bug Library Plugin Cross-Site Scripting Admin+ Stored XSS < 2.1.2 Fixed in 2.1.2 CVE-2024-5604 WPScan
6.5 Medium ArtPlacer Widget Plugin artplacer-widget Broken Access Control Subscriber+ Arbitrary Widget Deletion < 2.21.2 Fixed in 2.21.2 CVE-2023-7268 WPScan
4.3 Medium Duplica Plugin duplica Broken Access Control Authenticated (Subscriber+) Missing Authorization to Users/Posts Duplicates Creation ≤ 0.6 CVE-2024-5997 Wordfence
5.3 Medium ElementsKit Elementor addons Plugin elementskit-lite Information Disclosure Unauthenticated Information Exposure via ekit_widgetarea_content Function No login needed ≤ 3.2.0 CVE-2024-6455 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.6.5 CVE-2024-5555 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.6.11 CVE-2024-5554 Wordfence
5.4 Medium SVG Support Plugin svg-support Cross-Site Scripting Authenticated (Author+) Cross-Site Scripting via SVG ≤ 2.5.7 CVE-2023-6708 Wordfence
5.5 Medium RegLevel Plugin reglevel Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.2.1 CVE-2024-6705 Wordfence
4.3 Medium Meks Video Importer Plugin meks-video-importer Broken Access Control Missing Authorization to Authenticated (Subscriber+) API Keys Modification ≤ 1.0.12 CVE-2024-6599 Wordfence
6.4 Medium Zenon Lite Theme zenon-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode ≤ 1.9 CVE-2024-5964 Wordfence
5.4 Medium Booking Ultra Pro Plugin booking-ultra-pro Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Settings Updates ≤ 1.1.13 CVE-2024-6175 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only